Computer and Modernization ›› 2022, Vol. 0 ›› Issue (10): 47-54.

Previous Articles     Next Articles

ABAC Decision Recycling with Dynamic Policy Change

  

  1. (College of Mathematics and System Science, Xinjiang University, Urumqi 830046, China)
  • Online:2022-10-20 Published:2022-10-21

Abstract: Attribute-based access control (ABAC) becomes one of the most prominent access control models, as it is flexible and highly expressive. However, in ABAC, the burdened policy query tasks of policy decision point (PDP) and the communication between the PDP and policy enforcement point (PEP) affect the efficiency of access control decision making. Recycling of access control decision results is an effective solution for the above problem. This paper proposes an approach of access control decision recycling for ABAC, which supports dynamic policy change, with policy recycling. The presented approach specifies how to create and update the cache of the access control decision and how to make precise and approximate access control decisions based on the contents of the cache. Finally, we verify the feasibility and effectiveness of the approach by a prototype system test. Test results show that the presented approach can shorten the decision time of the access control system and reduce the burden of the PDP.

Key words: attribute-based access control, closed-world policy, open-world policy, hybrid policy, decision recycling